Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4374

Опубликовано: 16 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4374: file security update (MODERATE)

[5.33-20]

  • rebuild (#1954434)

[5.33-18]

  • fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

[5.33-17]

  • improve magic for script recognition and other changes (#1903531)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

file

5.33-20.el8

file-devel

5.33-20.el8

file-libs

5.33-20.el8

python3-magic

5.33-20.el8

Oracle Linux x86_64

file

5.33-20.el8

file-devel

5.33-20.el8

file-libs

5.33-20.el8

python3-magic

5.33-20.el8

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVSS3: 7.8
redhat
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVSS3: 7.8
nvd
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CVSS3: 7.8
debian
почти 6 лет назад

cdf_read_property_info in cdf.c in file through 5.37 does not restrict ...

suse-cvrf
около 5 лет назад

Security update for file